Order, validate and install an SSL certificate
Create a key and CSR with OpenSSL, configure your SSL order, validate the domain and install the certificate on nginx, Apache, IIS, cPanel or Plesk.
- Intermediate
- 20 min read
- Updated
Tested on: Ubuntu 24.04 LTS, Ubuntu 26.04 LTS, Debian 12, Debian 13, Windows Server 2022, Windows Server 2025
On this page
An SSL (TLS) certificate binds your domain to a key, so browsers can encrypt the connection and check that they reach the right server. This guide takes a purchased certificate from the private key to a working HTTPS site, and covers free certificates too. Replace example.com with your domain.
Before you start
- The domain points to the server: point a domain to your server.
- Choose the type: DV (domain validation, minutes), OV or EV (organisation checks, usually a few business days) or a wildcard for all subdomains. See SSL certificates.
- On hosting plans, the included free certificate may already be all you need: check SSL/TLS Status in cPanel or SSL/TLS Certificates in Plesk.
Step 1: Create a private key and CSR
On your server (or any Linux or macOS machine), create an ECDSA key and a certificate signing request that covers the domain and www:
openssl req -new -newkey ec -pkeyopt ec_paramgen_curve:prime256v1 -nodes -keyout example.com.key -out example.com.csr -subj "/CN=example.com" -addext "subjectAltName=DNS:example.com,DNS:www.example.com"If a system needs RSA, use -newkey rsa:2048 instead of the two ec options. Protect the key:
chmod 600 example.com.key
openssl req -in example.com.csr -noout -textVerify: the output shows your domain under Subject and Subject Alternative Name. The .key file stays on the server; you submit only the .csr.
Step 2: Configure the certificate in the client area
- Go to Services › My Services and open the SSL certificate service, then Configure SSL Certificate (or use Manage SSL Certificates).
- Choose your server type, paste the full CSR including the
BEGINandENDlines, and complete the contact details. - Choose a validation method, as offered for your certificate:
- Email: approve the message sent to an address such as
[email protected]or[email protected]. - DNS: publish the TXT or CNAME record you are given at your DNS host.
- HTTP file: place the given file under
/.well-known/pki-validation/on your site.
- Email: approve the message sent to an address such as
Verify: the order status moves to issued, and the certificate and CA bundle are delivered. DV certificates usually arrive within minutes of validation; OV and EV need the organisation checks first.
Step 3: Install the certificate
Save the certificate as example.com.crt and the intermediate bundle as ca-bundle.crt next to the key, for example in /etc/ssl/example.com/. For nginx and Apache, combine them into a full chain:
cat example.com.crt ca-bundle.crt > fullchain.pemnginx
server {
listen 443 ssl;
listen [::]:443 ssl;
server_name example.com www.example.com;
ssl_certificate /etc/ssl/example.com/fullchain.pem;
ssl_certificate_key /etc/ssl/example.com/example.com.key;
}Test and reload: sudo nginx -t and sudo systemctl reload nginx.
Apache
Enable the module, then set the files in the VirtualHost for port 443:
sudo a2enmod sslSSLEngine on
SSLCertificateFile /etc/ssl/example.com/fullchain.pem
SSLCertificateKeyFile /etc/ssl/example.com/example.com.keyTest and reload: sudo apachectl configtest and sudo systemctl reload apache2.
IIS
Combine key, certificate and chain into a PFX file (on a Linux or macOS machine):
openssl pkcs12 -export -out example.com.pfx -inkey example.com.key -in example.com.crt -certfile ca-bundle.crtIn IIS Manager › Server Certificates, choose Import and select the PFX. (If you created the CSR in IIS, use Complete Certificate Request instead.) Then open the site's Bindings, add an https binding on port 443 with the host name and select the certificate.
cPanel and Plesk
- cPanel: SSL/TLS › Manage SSL sites: paste the certificate, the key and the CA bundle for the domain and install.
- Plesk: SSL/TLS Certificates for the domain: upload the certificate, key and CA bundle, then select the certificate in the hosting settings.
Step 4: Check the result
echo | openssl s_client -connect example.com:443 -servername example.com 2>/dev/null | openssl x509 -noout -subject -issuer -datesVerify: the subject is your domain, the issuer is your certificate authority, and notAfter is in the future. Open the site in a browser and check the padlock. Redirect HTTP to HTTPS once everything works.
Free certificates with Certbot
On your own Linux server, Certbot obtains and renews Let's Encrypt certificates. Install it from the distribution packages and let it configure nginx:
sudo apt install certbot python3-certbot-nginx
sudo certbot --nginx -d example.com -d www.example.com
sudo certbot renew --dry-runUse python3-certbot-apache and --apache for Apache. A step-by-step setup with a reverse proxy is in nginx reverse proxy with Certbot.
Renewals and CAA
Maximum certificate lifetimes are shrinking: 200 days since 15 March 2026, 100 days from 15 March 2027 and 47 days from 15 March 2029. Multi-year purchases are reissued within the term, and you install each new certificate, so automate where you can. If you publish a CAA record, list every certificate authority you use, including the one behind free certificates:
dig CAA example.com +shortTroubleshooting
The browser warns about an incomplete chain. The CA bundle is missing; install the full chain.
"Key values mismatch" or the server does not start. The certificate does not belong to the key. Compare: openssl x509 -noout -pubkey -in example.com.crt and openssl pkey -pubout -in example.com.key must print the same key.
Validation by email never arrives. Use DNS or HTTP validation, or make sure the approver address exists.
Validation fails because of CAA. Add the issuing authority to your CAA record.
Next steps
- Put Cloudflare in front with Full (strict): Cloudflare setup.
- Compare certificate types: SSL certificates.
Frequently asked questions
Do I need to buy a certificate?
Not always. Hosting plans include a free certificate, and on your own server Certbot gets free Let's Encrypt certificates. Buy a certificate when you need organisation or extended validation, a commercial wildcard or a specific brand.
How long is a certificate valid?
Since 15 March 2026 a publicly trusted certificate can be valid for at most 200 days; the limit drops to 100 days on 15 March 2027 and to 47 days on 15 March 2029. Multi-year terms are subscriptions in which the certificate is reissued.
Where is my private key?
On the machine where you created the CSR, never in the certificate email. Keep it secret and back it up; without it the certificate cannot be installed.
What is the CA bundle or chain?
Intermediate certificates that link your certificate to a trusted root. Install them together with your certificate, or some browsers and apps show errors.
Do I need a dedicated IP address for SSL?
No. Server Name Indication (SNI) lets many sites with their own certificates share one IP address, and every current browser supports it.
Sources
- docs.openssl.org/3.0/man1/openssl-req
- docs.openssl.org/3.0/man1/openssl-s_client
- docs.openssl.org/3.0/man1/openssl-pkcs12
- nginx.org/en/docs/http/configuring_https_servers.html
- httpd.apache.org/docs/2.4/mod/mod_ssl.html
- certbot.eff.org/instructions
- cabforum.org/working-groups/server/baseline-requirements
- rfc-editor.org/rfc/rfc8659
- hyperdc.com/ssl-certificates